Skip to content

Commit f64c3fe

Browse files
Locked versions for releases: 7.16,8.0,8.1,8.2,8.3,8.4 (elastic#2236)
Co-authored-by: terrancedejesus <terrancedejesus@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit cb2ca45)
1 parent 17cfe15 commit f64c3fe

File tree

2 files changed

+1494
-1324
lines changed

2 files changed

+1494
-1324
lines changed

detection_rules/etc/deprecated_rules.json

Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,11 @@
2929
"rule_name": "User Discovery via Whoami",
3030
"stack_version": "7.14.0"
3131
},
32+
"125417b8-d3df-479f-8418-12d7e034fee3": {
33+
"deprecation_date": "2022/07/25",
34+
"rule_name": "Attempt to Disable IPTables or Firewall",
35+
"stack_version": "7.16"
36+
},
3237
"139c7458-566a-410c-a5cd-f80238d6a5cd": {
3338
"deprecation_date": "2021/04/15",
3439
"rule_name": "SQL Traffic to the Internet",
@@ -39,6 +44,16 @@
3944
"rule_name": "Linux Restricted Shell Breakout via c89/c99 Shell evasion",
4045
"stack_version": "7.16"
4146
},
47+
"20dc4620-3b68-4269-8124-ca5091e00ea8": {
48+
"deprecation_date": "2022/07/25",
49+
"rule_name": "Auditd Max Login Sessions",
50+
"stack_version": "7.16"
51+
},
52+
"3605a013-6f0c-4f7d-88a5-326f5be262ec": {
53+
"deprecation_date": "2022/08/01",
54+
"rule_name": "Potential Privilege Escalation via Local Kerberos Relay over LDAP",
55+
"stack_version": "7.16"
56+
},
4257
"3a86e085-094c-412d-97ff-2439731e59cb": {
4358
"deprecation_date": "2021/03/03",
4459
"rule_name": "Setgid Bit Set via chmod",
@@ -74,6 +89,11 @@
7489
"rule_name": "Query Registry via reg.exe",
7590
"stack_version": "7.14.0"
7691
},
92+
"6ea71ff0-9e95-475b-9506-2580d1ce6154": {
93+
"deprecation_date": "2022/08/02",
94+
"rule_name": "DNS Activity to the Internet",
95+
"stack_version": "7.16"
96+
},
7797
"6f1500bc-62d7-4eb9-8601-7485e87da2f4": {
7898
"deprecation_date": "2021/04/15",
7999
"rule_name": "SSH (Secure Shell) to the Internet",
@@ -94,6 +114,11 @@
94114
"rule_name": "Network Sniffing via Tcpdump",
95115
"stack_version": "7.14.0"
96116
},
117+
"7b08314d-47a0-4b71-ae4e-16544176924f": {
118+
"deprecation_date": "2022/08/02",
119+
"rule_name": "File and Directory Discovery",
120+
"stack_version": "7.16"
121+
},
97122
"7d2c38d7-ede7-4bdf-b140-445906e6c540": {
98123
"deprecation_date": "2021/04/15",
99124
"rule_name": "Tor Activity to the Internet",
@@ -124,6 +149,11 @@
124149
"rule_name": "Linux Restricted Shell Breakout via apt/apt-get Changelog Escape",
125150
"stack_version": "7.16"
126151
},
152+
"90e28af7-1d96-4582-bf11-9a1eff21d0e5": {
153+
"deprecation_date": "2022/07/25",
154+
"rule_name": "Auditd Login Attempt at Forbidden Time",
155+
"stack_version": "7.16"
156+
},
127157
"97da359b-2b61-4a40-b2e4-8fc48cf7a294": {
128158
"deprecation_date": "2022/05/09",
129159
"rule_name": "Linux Restricted Shell Breakout via the SSH command",
@@ -169,6 +199,11 @@
169199
"rule_name": "Nmap Process Activity",
170200
"stack_version": "7.14.0"
171201
},
202+
"cab4f01c-793f-4a54-a03e-e5d85b96d7af": {
203+
"deprecation_date": "2022/07/25",
204+
"rule_name": "Auditd Login from Forbidden Location",
205+
"stack_version": "7.16"
206+
},
172207
"cc16f774-59f9-462d-8b98-d27ccd4519ec": {
173208
"deprecation_date": "2021/04/15",
174209
"rule_name": "Process Discovery via Tasklist",
@@ -184,6 +219,11 @@
184219
"rule_name": "PPTP (Point to Point Tunneling Protocol) Activity",
185220
"stack_version": "7.14.0"
186221
},
222+
"d6450d4e-81c6-46a3-bd94-079886318ed5": {
223+
"deprecation_date": "2022/07/28",
224+
"rule_name": "Strace Process Activity",
225+
"stack_version": "7.16"
226+
},
187227
"da986d2c-ffbf-4fd6-af96-a88dbf68f386": {
188228
"deprecation_date": "2022/05/09",
189229
"rule_name": "Linux Restricted Shell Breakout via the gcc command",
@@ -194,6 +234,16 @@
194234
"rule_name": "Threat Intel Filebeat Module (v7.x) Indicator Match",
195235
"stack_version": "8.0"
196236
},
237+
"df959768-b0c9-4d45-988c-5606a2be8e5a": {
238+
"deprecation_date": "2022/07/25",
239+
"rule_name": "Unusual Process Execution - Temp",
240+
"stack_version": "7.16"
241+
},
242+
"e0dacebe-4311-4d50-9387-b17e89c2e7fd": {
243+
"deprecation_date": "2022/08/02",
244+
"rule_name": "Whitespace Padding in Process Command Line",
245+
"stack_version": "7.16"
246+
},
197247
"e56993d2-759c-4120-984c-9ec9bb940fd5": {
198248
"deprecation_date": "2021/04/15",
199249
"rule_name": "RDP (Remote Desktop Protocol) to the Internet",
@@ -219,6 +269,11 @@
219269
"rule_name": "Linux Restricted Shell Breakout via flock Shell evasion",
220270
"stack_version": "7.16"
221271
},
272+
"fb9937ce-7e21-46bf-831d-1ad96eac674d": {
273+
"deprecation_date": "2022/07/25",
274+
"rule_name": "Auditd Max Failed Login Attempts",
275+
"stack_version": "7.16"
276+
},
222277
"fd3fc25e-7c7c-4613-8209-97942ac609f6": {
223278
"deprecation_date": "2022/05/09",
224279
"rule_name": "Linux Restricted Shell Breakout via the expect command",

0 commit comments

Comments
 (0)